git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] contrib: remove gitview

From
Jeff King <peff@peff.net>
Date
Dec 29, 2016, 01:59 UTC
Message-ID
<20161229015918.jyiqd42z4htjibul@sigill.intra.peff.net>
In-Reply-To
<20161228172837.24395-1-sbeller@google.com>
On Wed, Dec 28, 2016 at 09:28:37AM -0800, Stefan Beller wrote:
Show 18 quoted lines
> gitview did not have meaningful contributions since 2007, which gives the
> impression it is either a mature or dead project.
> 
> In both cases we should not carry it in git.git as the README for contrib
> states we only want to carry experimental things to give early exposure.
> 
> Recently a security vulnerability was reported by Javantea, so the decision
> to either fix the issue or remove the code in question becomes a bit
> more urgent.
> 
> Reported-by: Javantea <jvoss@altsci.com>
> Signed-off-by: Stefan Beller <sbeller@google.com>
> ---
>  contrib/gitview/gitview     | 1305 -------------------------------------------
>  contrib/gitview/gitview.txt |   57 --
>  2 files changed, 1362 deletions(-)
>  delete mode 100755 contrib/gitview/gitview
>  delete mode 100644 contrib/gitview/gitview.txt

Thanks for assembling the patch. This seems reasonable to me, though I'd like to get an Ack from Aneesh if we can.

-Peff
Previous: JavanteaNext: Junio C Hamano
Message 6 of 8 in “Gitview Shell Injection Vulnerability”
  1. JavanteaDec 27, 2016
  2. Stefan BellerDec 27, 2016
  3. Jeff KingDec 28, 2016
  4. contrib: remove gitviewStefan Beller, Dec 28, 2016
  5. JavanteaDec 28, 2016
  6. Jeff KingDec 29, 2016
  7. Junio C HamanoJan 1, 2017
  8. Aneesh Kumar K.VJan 2, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.